ai-quant-engineering
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill describes tools for news sentiment analysis and news-based decision making (
tools/news_sentiment.py). This ingestion of untrusted external data sources creates a surface for indirect prompt injection, where instructions hidden in news content could attempt to influence the agent's trading logic or research outcomes. - Ingestion points: External news data and sentiment analysis tools (
news_sentiment.py,news_analysis). - Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions for external data content.
- Capability inventory: The system includes capabilities for autonomous trading (
auto_trader.py), order execution (trade_executor.py), and strategy backtesting. - Sanitization: No explicit sanitization or validation of the external news text is described in the provided skill context.
- [COMMAND_EXECUTION]: The architecture utilizes subprocess spawning from a Rust backend to run Python scripts across different virtual environments. The
backtest_strategytool accepts astrategy_codestring, which suggests dynamic execution of code provided to the tool. While this aligns with the primary purpose of a quantitative research environment, it represents a capability for executing arbitrary code logic.
Audit Metadata